Martin Paljak
> According to the openvpn-docu, (at the server-side) one of their environment 
> variables, "tls_id_0" should contain the hexadecimal value of the certificate.
> In reality in contains completely other fields, like CN=, OU=, O= and C=.

I guess the tls_id_0 should contain exactly this, the subject of the

> Is there any tool to lookup the serialnumber of a certificate stored on a 
> smartcard directly?
> I know I can export the certificate manually and use openssl to analyse it, 
> but can it be done with one of the pkcs* open opensc* tools?

pkcs15-tool --read-certificate <num> | openssl x509 -text

Would like to try it, but the pkcs15-tool fails with "unsupported card"

With pkcs11-tool I hev to provide "--module /usr/lib/libaetpkss.so.3.0" .
But pkcs15-tool does not have the "--module" option.


